
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
CLI para iniciar projetos com arquivos base do Dalhe.
dalhe init copia template de src/template/init para diretorio atual e prepara estrutura inicial do projeto.
Hoje template inclui:
AGENTS.mdCLAUDE.md.ai-framework/DESIGN.md.ai-framework/RULES.md.ai-framework/skills/caveman/SKILL.mdSe algum arquivo de destino ja existir, comando para e nao sobrescreve nada.
>=25.4.0npm install -g dalhe-cli
npm install -g github:alexishida/dalhe-cli
No repositorio do projeto:
npm pack
npm install -g .\dalhe-cli-0.1.1.tgz
No repositorio do projeto:
npm install -g .
Entre na pasta onde deseja criar base do projeto:
dalhe init
Exemplo:
mkdir meu-projeto
cd .\meu-projeto
dalhe init
dalhe init
dalhe --help
dalhe -h
dalhe --version
dalhe -v
initbin/dalhe.js: ponto de entrada do CLI.src/commands: comandos da aplicacao.src/core: base da execucao e tratamento de erros.src/services: servicos de apoio.src/template/init: template copiado pelo comando init.test: testes automatizados.npm install
npm test
node .\bin\dalhe.js --help
Para testar fluxo completo sem instalar globalmente:
node .\bin\dalhe.js init
Antes de publicar, valide pacote final:
npm pack --dry-run
Depois publique nova versao:
npm publish
MIT
FAQs
CLI para iniciar projetos com arquivos base do Dalhe.
The npm package dalhe-cli receives a total of 8 weekly downloads. As such, dalhe-cli popularity was classified as not popular.
We found that dalhe-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.